3 ms·
I get that Troy is probably tired of receiving beg bounties, but as a security researcher himself, I find this post a bit distasteful and discouraging towards t
by Ayesh 3y ago
I get that Troy is probably tired of receiving beg bounties, but as a security researcher himself, I find this post a bit distasteful and discouraging towards the people who could as well be on their way to finding bigger vulnerabilities.
Reports on lack of SPF/DMARC records on security headers can be annoying, and often false, because there are some legitimate cases an SPF record with `~all` is necessary, or you have to have a permissive CSP for whatever reason.
I would have just deleted their email and moved on.
- eknkc 3y agoYou receive 20 mails each day and when you delete them you receive follow ups. You receive emails getting angry and the tone shifts to threats (as if the bug they are reporting warrants it). These bury any legitimate reports. We have missed a legit one because of the sheer amount of beggers at some point. Luckilty the person on the other end contacted us again and was understanding that we missed it. And there are some who do not disclose and act like there is a really critical issue, fishing for replies first and then dropping a pile of shit as a critical security issue. I'm also fed up with these.
- Ayesh 3y agoQuoted from the post: > It was _immediately_ clear that Hammad was going to beg for a bounty, but it was a quiet Saturday night here and I thought it would be entertaining to see just how far down the rabbit hole he wanted to go. So, I responded, positively: I suppose most of these useless bounty reports are quite easy to tell. From the comment above: > 20 mails each day If you receive 20 mails a day to your security email address, then, perhaps it's time to setup a proper bug bounty program? They will weed out low impact vulnerabilities and only elevate the reports above a certain threshold. Isn't this a solved problem already?
- blincoln 3y agoFrom what I've seen secondhand, a bug bounty programme can actually increase the overhead vs. an email address, because now someone has to log in and deal with each ticket instead of ignoring emails that don't seem interesting. There are some significant advantages to having a bug bounty programme, but they still attract a lot of noise. I know of at least one software company that has an entire team just to triage the queue. Not fix anything, just validate whether a report ia reproducible or not and if so, route it to the responsible party.
- Ayesh 3y agoI participate in a couple programs, and when I report something, they have a team at the bug reporting service take a look first before escalating them to the actual security contact. Only issues that are in-scoope and severe enough get escalated. The company can even mark certain programs as invitee-only or for researchers above a certain threshold. Many programs already have rules saying they will not consider DNS/header related issues.